Advanced Threat Actors Shift Focus to Firmware-Level Persistence on FortiGate Devices
Fortinet has issued a critical advisory revealing that threat actors are maintaining unauthorized, read-only access to FortiGate devices even after…
Unpatched NVIDIA Container Toolkit Bug Could Let Attackers Escape Docker and Hijack Linux Hosts
In September 2024, NVIDIA addressed a critical vulnerability in its Container Toolkit, identified as CVE-2024-0132, which had a CVSS score…
Gamaredon Hackers Use Infected USB Drives to Target Western Military in Ukraine with GammaSteel Malware
The Russian-affiliated cyber-espionage group Gamaredon, also known as Shuckworm, has recently been implicated in a cyber attack targeting a Western…
Critical FortiSwitch Vulnerability (CVE-2024-48887) Prompts Urgent Firmware Updates from Fortinet
Fortinet has issued a critical security advisory concerning a significant vulnerability in its FortiSwitch product line. The flaw, designated as…
Apple Releases Security Updates to Fix Three Actively Exploited Zero-Day Vulnerabilities in iOS and macOS
Apple has released critical security updates to address three zero-day vulnerabilities actively exploited in the wild, extending these fixes to…
Russian Hackers Exploit CVE-2025-26633 in Microsoft MMC: Critical Zero-Day Vulnerability Under Attack
A Russian cybercriminal group, identified as Water Gamayun (also known as EncryptHub and LARVA-208), has been exploiting a zero-day vulnerability…
Google Releases Urgent Chrome Update to Patch Actively Exploited Zero-Day Vulnerability
Google has issued an emergency security update for its Chrome browser on Windows to address a high-severity zero-day vulnerability, identified…
Apache Tomcat CVE-2025-24813 Exploited in the Wild – Patch Now to Prevent Attacks
A critical security vulnerability identified as CVE-2025-24813 has been discovered in Apache Tomcat, a widely used open-source Java servlet container.…
GitHub Uncovers Critical Ruby-SAML Vulnerabilities: Urgent Patch Required
GitHub’s Security Lab has identified two severe vulnerabilities in the open-source ruby-saml library, which could enable attackers to bypass Security…
Microsoft Alerts on New ‘ClickFix’ Phishing Scam Targeting Hospitality Industry via Booking.com
In a recent cybersecurity alert, Microsoft has identified an ongoing phishing campaign targeting the hospitality sector by impersonating the online…







